Healthcare GRC

HIPAA Security Risk Assessment

Understand where electronic protected health information may be exposed and document a practical path for reducing risk.

What the Assessment Looks At

The assessment considers where electronic protected health information is created, received, maintained or transmitted; relevant threats and vulnerabilities; existing safeguards; and the likelihood and potential impact of identified risks.

Areas Commonly Reviewed

Depending on the practice environment, review areas may include user access, MFA, workstations, patching, backups and recovery, Microsoft 365, vendor access, remote access, network safeguards and the systems or locations where ePHI exists.

What You Receive

  • Assessment scope and ePHI inventory information
  • Documented risks, threats, vulnerabilities and safeguards
  • Prioritized risk register
  • Practical remediation plan
  • Management-ready summary for follow-up and documentation

Important Scope Note

A security risk assessment documents and evaluates risk; it is not a legal opinion or a guarantee of HIPAA compliance. The assessment must reflect the practice's actual environment, systems and safeguards.